SV-24668r1_rule
V-3821
DBMS application user privilege assignment review
DG0080-ORACLE11
CAT II
10
Develop, document and implement policy and procedures for periodic review of database user accounts and privilege assignments.
Include methods to provide evidence of review in the procedures to verify reviews occur in accordance with the procedures.
Review policy, procedures and implementation evidence to determine if periodic reviews of user privileges by the IAO are being performed.
Evidence may consist of email or other correspondence that acknowledges receipt of periodic reports and notification of review between the DBA and IAO or other auditors as assigned.
If policy and procedures are incomplete or no evidence of implementation exists, this is a Finding.
V-3821
False
DG0080-ORACLE11
Review policy, procedures and implementation evidence to determine if periodic reviews of user privileges by the IAO are being performed.
Evidence may consist of email or other correspondence that acknowledges receipt of periodic reports and notification of review between the DBA and IAO or other auditors as assigned.
If policy and procedures are incomplete or no evidence of implementation exists, this is a Finding.
I
Database Administrator
1367